Cisco AAA/Identity/Nac :: ISE - WLC 7.2 VLAN Assignment?

Sep 10, 2012

The Wireless_Employees authorization profile,assign vlan 666 for wireless employees.ISE is passing VLAN 666 to the WLC - see attachement Radius Auth-VLAN666.jpg then I look on the WLC at a wireless employee who has successuflly connected to the network, WLC is still placing him in the pre-configured VLAN 7.

1. can VLAN be pushed from ISE to the WLC (code 7.2.103) for specific user session?

View 3 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: Guest Vlan - Assignment Error On 3560 Switch?

May 18, 2013

I am configuring 802.1X in a 3560 Switch, my Radius server is a Microsoft IAS, when I connect a station of a guest user, the guest-vlan is not assigned in the port, and I have these logs:
 
May  8 21:23:02: dot1x-ev:Received an EAP Timeout on FastEthernet0/8 for mac 0000.0000.0000
May  8 21:23:02: dot1x-ev:dot1x_guest_vlan_applicable: Guest VLAN not

[Code].....

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS4.1 - Radius Dynamic VLAN Assignment Not Working?

Jan 28, 2013

When the users connect their laptop they are getting a authentication prompt but the switch is not changing the VLANs on the port after successful authentication.Below are the logs on the switch 
 
Jan 28 2013 17:21:32.417 CST: RADIUS:  Framed-MTU          [12]  6   1500
Jan 28 2013 17:21:32.417 CST: RADIUS:  Called-Station-Id   [30]  19  "E4-D3-F1-0B-C6-0A"
Jan 28 2013 17:21:32.417 CST: RADIUS:  Calling-Station-Id  [31]  19  "84-8F-69-A8-BD-1D"
Jan 28 2013 17:21:32.417 CST: RADIUS:  EAP-Message         [79]  45

[code]....

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 3750x / Dynamic VLAN Assignment For Wired Campus Network

Nov 23, 2012

I`m working on Dynamic Vlan Assigmenton the basis of end user authenticatedwhoc are part of specific AD Group in c ampus enviorment.Objective: Need to assign the vlan on switch port on the basis of authenticated users OU Group in Active Directory. Eg: There are 2 OU groups in AD, Sales and Administration. Authenticated user in Sales group should get Vlan 10 and user in Admininstration Group shoudl get Vlan 20.
 
Components:
 
Cisco 3750x/Cisco 4500
ACS Version 5.2
Microsoft AD

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Use 802.1x To Authenticate Clients On Network With Dynamic VLAN Assignment From RADIUS?

Apr 11, 2013

I'm trying to use 802.1x to authenticate clients on my network with dynamic VLAN assignment from RADIUS. We have IP-Phones(powered by PoE) that only supports EAP-MD5, and we would rather use MAB(it also uses LLDP-MED for some settings) to authenticate the phones using the MAC-range from the phones vendor. The following scenario works perfect:Connect the phone and let it boot up(takes a while) and authenticate with MAB.Connect a computer in the phones data-port and let it authenticate with 802.1x(or fail and reach guest-vlan) However, the following scenario doesn't work:The computer is already connected to the phoneThe phone is then connected to the switch What happends now is that the computer is authenticated using 802.1x before the phone boots up and get's authenticated with MAB. When the phone is ready, it's authenticated with MAB and everything works. However, after a short period(let's say a minute), using `debug authentication all`, we see a "NEW LL MAC: phones mac" message(which is weird since the mac has already been MAB-authenticated), and then we are unable to contact the phone using ping. When I check `show mac address-table` it has now moved the mac from `Port Gi 0/12` to `Port Drop`. However, if I check `show mab interface Gi 0/12` or `show authentication sessions` it lists the phones-mac as `mab auth sucess `.why the first scenario works, and not the second?
 
The switch is a 3560E PoE 24p with IOS 12.2.58SE2. Sample of the switch-config: network-policy profile 1voice vlan 90!interface GigabitEthernet0/12switchport mode accessnetwork-policy 1authentication control-direction inauthentication event fail retry 1 action authorize vlan 60authentication event server dead action authorize vlan 60authentication event no-response action authorize vlan 60authentication event server alive action reinitializeauthentication host-mode multi-domainauthentication order mab dot1xauthentication priority mab dot1xauthentication port-control autoauthentication periodicauthentication violation replacemabdot1x pae authenticatordot1x timeout tx-period 5dot1x max-reauth-req 1spanning-tree portfast!Btw, when we tried authenticating the phones using 802.1x too (EAP-MD5), there are NO problems in any of the scenarios. However, we want to use MAB instead of 802.1x to avoid the requirement of configuring the phones with a username and password. The RADIUS response was the same when using 802.1x as it is with MAB for the phones (including device-traffic-class=voice AV-pair).

View 2 Replies View Related

Cisco Wireless :: VLAN Assignment Without ACS On 5508

Apr 8, 2013

I was wondering if it is possible to do dynamic VLAN assignment on the Cisco Wireless Controller 5508 without using Cisco ACS but use Microsoft NPS server instead?

View 3 Replies View Related

Cisco :: WLC 4.0 - Dynamic VLAN Assignment And DHCP

Jan 16, 2011

I have just upgraded our WLC from 4.0 to 7.0 (via 4.2). Before the upgrade we had our ACS returning a VLAN based on user group.  This seemed to be working without an issue.  Now that the WLC is on version 7 this is no longer working correctly.  The ACS is returning a VLAN and passing the user but the client can not get an IP from the DHCP server configured.
 
Example configuration:
 
SSID-----VLAN
 
PN-CSC-----CSCVlan: Works
PN-Others------OthersVlan: Works
 
PN-Others-----CSCVlan: No DHCP
 
When users are trying to be allocated to a vlan that is different from the native one the DHCP fails however both WLANs are configured to point to the management interface so dont have any real connection to the vlan other than by name.
 
Have there been any changes I haven't seen in the way the dynamic vlan allocation works in version 7?

View 8 Replies View Related

Cisco :: Dynamic Vlan Assignment With 1242AG And IAS Not Working

Dec 13, 2012

I'm having trouble getting the dynamic vlan assignment to work on my 1242AG Cisco Aironet APs. I've seen multiple cases with a similar setup and configuration where it works just fine.  I've tried everything I can think of. IAS and AD is running on Windows Server 2003.Everything works fine except the vlan assignment.  Wireless clients successfully authenticate through IAS and Active Directory, but instead of being switched to the appropriate vlan the client stays in whichever vlan/ssid it originally connected to.PEAP is the authentication method, using MS-CHAP v2.  Naturally I have the attributes in the policy set appropriately,[code] I've attached the config for the AP, which shows that I have two vlans/SSIDs set to cipher, aes, network eap, wpa, etc. I noticed that if the Tunnel-Pvt-Group-ID attribute is set to a vlan id that doesn't exist on the AP then the AP makes an event log saying so.

View 16 Replies View Related

Cisco Wireless :: WAP4410N 802.1x Dynamic VLAN Assignment?

Nov 27, 2012

Does the WAP4410N support Dynamic VLAN assignment by means of 802.1x authentication?
 
The reason why I ask this; I am able to configure a SSID on a WAP4410N with WPA2-Enterprise, in combination with 802.1x PEAP network authentication. I can succesfully connect Windows, Windows RT, Windows Phone, iOS and Android devices. But.. I am unable to designate them to another VLAN based on access/connection policies. For example; I want mobile devices such as iPhone and Windows Phone to be assigned to a specific VLAN. The Wireless Access Point (authenticator) must be able to support that.
 
This is my setup:
 
Spplicants: Windows 8 / iPad / ...
Authenticator: WAP4410N
Authentication Server: Microsoft NPS (Network Policy Server)
 
I used 802.1x PEAP (Protected EAP) with password (domain user) authentication. In fact, the suplicants communicate with 802.1x to the authenticator. The authenticator communicates with RADIUS to the authentication server. NAP is not in between. It's just plain 802.1x authentication.
 
wether dynamic VLAN assignment is supported?

View 5 Replies View Related

Cisco Switches :: Dynamic VLAN Assignment And Layer 3 Switching On 300 Series?

Jul 11, 2012

I have a SG300-28P switch. I just read in the Administration Guide that, when in Layer 3 mode, the switch doesn't support MAC-based VLAN or Dynamic VLAN Assignment.
 
So, in order to assign a client to a VLAN based on their MAC or based on the response of a RADIUS server, we have to disable layer 3 features. Without layer 3 switching, the switch is unable to act as a default gateway and forward packets between VLANs. As a result, the VLANs can't communicate in any way, or access the internet, unless a separate router is connected to every VLAN. Right? Doesn't this limitation significantly reduce the usefulness of the DVA feature?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Secure ACS 5 For IP Address Assignment Via RADIUS?

Jan 13, 2013

I want to use RADIUS (of Secure ACS 5.3) to authenticate users within an ISP environment. Users log connect to a network using a point to point connection (L2) and then they are sending a RADIUS request to get IP adresses. Secure ACS is not quite easy to look through in that case.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Device Admin Privilege Assignment?

Dec 1, 2011

my admin user is still being assigned privilege level 1, as shown in AAA Protocol > TACACS+ Authentication Details report.The report seems to show that the user is getting the right shell profile (Selected Shell Profile: Net-Admin -- is the one I setup for this user's group with both Default Privilege and Maximum Privilege set to Static 15). But still not the right privilege (Privilege Level: 1).Also, I found this document via Google: [URL] The router configuration examples all show this "aaa authorization exec tacacs+|radius local" command, which my device does not have.So I am wondering if I am not reading the ACS report right, or the device actually was assigned the correct privilge but that does not work without the "aaa authorization exec" command in the configuration?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Static IP Assignment For Local User

Jun 7, 2011

how I can assign a static IP to a user in ACS 5.2. I am able to do it in ACS 4.2, but I don't see the same options under 5.2. General idea is that users authenticate from our VPN appliance via RADIUS, and upon authentication, their static IP is passed back to the VPN device. I can attach an arbitrary field to my local users by going to System Administration -> Configuration -> Dictionaries -> Identity -> Internal Users, but how do I get that IP address passed back when the user is authenticated via Radius?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 802.1x Auth-Fail VLAN And Guest-VLan Not Available

Oct 12, 2011

I'm wanting to setup a Virtual Office scenario. Everything is working fine except for 802.1x...I can get the 881 to authenticate things connected to it, but I don't have the options of guest-vlan or auth-fail vlan.Idea is if the users takes the router home and someone, either accidentally or on pupose, connects an unauthorized Laptop, they stay off the Corp network but can get to the internet still.I found this link on Cisco's site: [URL]That link shows them configuring a guest vlan right on the fa0-3 ports of an 881W. I dont have that option on mine. I can only configure 802.1x on the vlan interface. I have 802.1x working, for things that connect to vlan1, but I would like to have a "fallback" setup.
 
EZVPN_Remote(config-if)#int fa1
EZVPN_Remote(config-if)#dot
EZVPN_Remote(config-if)#dot1?
dot1q 
EZVPN_Remote(config-if)#dot1

[code]....

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Authentication MAB And Set Guest VLAN

Jul 13, 2011

is it possible to set the dot1x guest-vlan on a Catalyst Switch via ACS 5.2 dynamicly. I want to make MAB with known Devices (FAT-Clients, Notebooks,  Desktops, Printers) and unknown Devices.I will set the VLAN dynamicly with dot1x per ACS. For known FAT-Clients, Notebooks etc. it's running well.But for Printers it's more difficult because I have about 500 Printers in several IP-Segments on several Switches and I will not make to much Rules in ACS for Grouping, Mapping and Authority-Rules.My Idea is to set the Guest-VLAN on every Switch, read them with ACS and use this for my Printers.The Problem is that Guest-VLAN is set on more than 100 Switch and this guest-vlan is different on any Switch.Can I read the Geust-VLAN Value so that I can set this via ACS ?

View 4 Replies View Related

Cisco AAA/Identity/Nac :: Dot1x Guest VLAN On 2960G

Apr 9, 2012

I have a 2960 sw configured for dot1x authentication, the problem is the Guest VLAN and Restricted VLAN didnot work. The switch port was stuck in authenticating status. The server is Juniper IC4500.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Doc Covering Using ACS 5.3 To Control Guest VLAN

Oct 10, 2012

I've configured an ACS 5.3 system and all my groups etc fucniton corrcetly both for Network Access and for Device Administration.

However I'm stuck trying to allow clients to authenticate against the router's web-page i.e. Web-Authenticaiton, using TACACS+ between the router and the ACS5.3.
 
I've looked into this and I need to configure a custom-attribute of "service" with type Outbound and link this to an Authorization policy.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Assign VLAN Based On AD Group?

Apr 18, 2011

I'm trying to configure ACS 5.2 to assign the VLAN to a user dynamically based on the AD group that the user belongs to. I've gone into:
 
Users and Identity Stores -> External Identity Stores -> Active Directory -> Directory Groups tab
 
and selected the group name from the AD. If I understand correctly, I should now see this group under:
 
Policy Elements -> Authorization and Permissions -> Network Access -> Authorization Profiles -> Common Tasks -> VLAN ID/Name
 
However, it does not. Am I missing something?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Failed Authenticate With Same Voice And Data Vlan

Apr 14, 2011

I have a question its posible to authenticate an cisco phone and PC with the same vlan(voice and data)when i do this configuratión , the phone and pc dont work. The phone display registering and never finished.interface FastEthernet0/5 switchport mode access switchport voice vlan 1 authentication event fail action authorize vlan 11 authentication event no-response action authorize vlan 11 authentication host-mode multi-domain authentication port-control auto authentication periodic authentication violation protect mab dot1x pae authenticator dot1x timeout tx-period 10 dot1x max-reauth-req 3 spanning-tree portfastend.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: WS-C4510R Critical Voice Vlan Support

Dec 15, 2011

Critical voice vlan feature, used to place a newly authenticating phone when radius server is dead into appropriate voice vlan, seems to be a new feature and I find the documentation to be incomplete.  Do the following switches support this feature in any IoS versions? WS-C4510R, 4506, 3560, 3550,2960s.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Configure Guest Vlan And Restricted On 2960

Apr 17, 2011

I would like to configure a guest-vlan and restricted-vlan on a 2960 switch, but I can not.
 
I am trying to configure the interface using the following commands: [code] similar result is obtained while trying to configure a auth-fail vlan. the full configuration file is attached.

View 4 Replies View Related

WNDR3700 IP Assignment?

Apr 1, 2012

In the settings, there is a spot in which you can set the range of IPs to assign to connected computers and other devices. This particular option is available under the "LAN" options. What I am seeing is that the only IP that is assigned within the range is the one and only device hardwired to the router. Everything else is being assigned IP addresses outside of the range. Am I missing something? I was under the assumption that any IP addresses assigned dynamically would be within the range whether they were wired or wireless

View 10 Replies View Related

Cisco AAA/Identity/Nac :: C3560E / Authentication Event Fail Action Authorize VLan

Jul 15, 2012

when the supplicant is missing vlan500 is open for port and everything is ok, but when supplicant has wrong configuration something happend and port is always authenticating(every 30s, vlan500 is not assign to this port with bad configuration supplicant) and logs show something like that
 
Jul 10 10:20:12.362: %AUTHMGR-5-START: Starting 'dot1x' for client (001e.3718.7297) on Interface Ga0/1 AuditSessionID 0A0EFF5B000004A3545161E4 Jul 10 10:20:44.365: %AUTHMGR-5-START: Starting 'mab' for client (001e.3718.7297) on Interface Ga0/1 AuditSessionID 0A0EFF5B000004A45451DF11 Jul 10 10:20:44.399: %MAB-5-FAIL: Authentication failed for client (001e.3718.7297) on Interface Ga0/1AuditSessionID 0A0EFF5B000004A45451DF11 Jul 10 10:20:44.399: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'mab' for client (001e.3718.7297) on Interface Ga0/1 AuditSessionID 0A0EFF5B000004A45451DF11 Jul 10 10:20:44.399: %AUTHMGR-7-FAILOVER: Failing over from 'mab' for client (001e.3718.7297) on Interface Ga0/1 AuditSessionID 0A0EFF5B000004A45451DF11 Jul 10 10:20:44.399: %AUTHMGR-5-START: Starting 'dot1x' for client (001e.3718.7297) on Interface Ga0/1 AuditSessionID 0A0EFF5B000004A45451DF11
  
version - Cisco IOS Software, C3560E Software (C3560E-UNIVERSALK9-M), Version 15.0(1)SE2
  
port config:

interface GigabitEthernet0/1
switchport access vlan 104
switchport mode access
switchport voice vlan 200
authentication event fail action authorize vlan 500

[code]....

View 3 Replies View Related

Cisco VPN :: ASA 8.2 - ACS 5.2 With Dynamic VPN IP Pool Assignment?

Aug 7, 2011

I have Remote Access VPN users (IPsec) who  are terminated on Cisco ASA 5520 (v8.2). For those users, AAA is done on the ACS.  Group-policies and tunnel groups are defined on ASA. Initialy I had all  VPN users defined on ASA and group policies were associated with each  user. Each group policy had it’s own IP pool for users. Now, I moved  users to ACS. How can I associate group policy, defined on ASA, with  users group defined on ACS? Is it possible that ACS send to ASA  information about IP pool for different group policy? Users will use ONE vpn profile BUT based on the Active Directory group they belong to they obtain a different IP address for each group.Can it be done ? ACS version is 5.2.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 3750 Fall Back To Local Vlan If Radius Server Is Found

Nov 14, 2012

We have configured following commands on switch to fallback to local Vlan if both radius server (policy persona's) is found dead. For test purpose we shutdown both servers (policy persona's) but fallback didn't work. We have 3750 switch running image 12.2(55)SE6 having following configuration.We do not know whether we configured switch in proper way or do we need to modify it. [code]

View 5 Replies View Related

Cisco :: ASA Dhcpd Server Assignment Based On Mac

Sep 24, 2011

is it possible to use the asa dhcp server function to assign based on mac address (yet)? I have read numerous places that it was not possible (as of 8.2) at least, but I am workin in 8.4. I should have mentioned that I've already tried commands (asa 5510 btw)

View 4 Replies View Related

Cisco :: Fictional Network Design Assignment

Mar 5, 2013

I have gotten the assignment of constructing a fictional network for my school.. and i cannot quite agree with myself upon which equipment i should choose.. its supposed to be all cisco. i need to supply 5000 users all in all, but only 300 on this site. i need to know which connections would be the most reasonable to use and of course which routers "if any" and switches i need.. (+ additional modules if needed) i have tried to make a visio representation, but i just think something is way off.

View 6 Replies View Related

Cisco WAN :: ACL NAT 3845 Static Assignment Has No Wan Connectivity

Mar 29, 2011

I'm having a strange issue with a Cisco 3845 ISR router. I am setting up basic ACL and NAT but 2 issues occur. When using pat (overload) and a static nat assignment on the same subnet, the host with the static assignment has no wan connectivity except for icmp. The host is not reachable via the wan and the static public ip. Running show ip nat translations show the correct inside local and inside global addresses. The other issue is when applying an extended ACL to the outside or WAN interface coming in. No host on the inside has connectivity (icmp, tcp etc.) even to the gateway. I've cleared out all the ACL's as well as the ipsec tunnel settings and created only the nat overload and a single static assignment with the same results.I'm posting the running config below.

version 15.1
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
[Code]...

View 13 Replies View Related

D-Link DIR-655 :: External IP Address Assignment?

Mar 3, 2011

I have a home desktop, home laptop, and work laptop that I use.  I have Ultra VNC setup on my work laptop that allows me to remote into that machine when I am traveling for work.  I have always been able to use the external IP address (not private) to login into the machine with no problem.  This week, for some reason, I can no longer do that.  When I started doing some discovery, I noticed that when I have all 3 machines booted up at home that the exact same external IP address is assigned to all 3 machines.  The internal IP addresses are all different as they should be.Shouldn't each machine have a seperate external IP address assigned as well?  Or is this working the way it should?  I didn't change any setting on my router or DSL model.  But I think the conflict that VNC is having on my work laptop is that it has the exact same IP as the destination computer and it fails.  I can remote in if I use the private IP address (192.168.x.x) just fine. 

View 1 Replies View Related

Cisco :: AIR-LAP-1242G APs Not Obeying Static IP Address Assignment

Feb 8, 2011

I've got a network of several AIR-LAP-1242G LWAPP access points controlled by a 2112 WLC. I assign static IP addresses to each LWAPP, but every few weeks, a couple of them (at random) revert back to grabbing a DHCP-assigned dynamic address for themselves, despite the fact that they're supposedly solidy configured to have static IPs. What's going on here? Is this a bug in their firmware or the WLC's firmware? If I reboot the APs, then they come up with their static IPs, but after running some random number of days/weeks, will spontaneously change their own management IP addresses and grab a DHCP address for themselves.
 
The 1242G APs version numbers reported by the WLC's web GUI are:

"Software version" 5.2.193.0
"Boot version" 12.4.13.0
"IOS version" 12.4(18a)JA2
"Mini IOS version" 3.0.51.0
 
The 2112 WLC is running software version 5.2.193.0

View 2 Replies View Related

Cisco Wireless :: AP Power Level Assignment 1252

Sep 1, 2011

We are using WiSM WLCs and WCS to control a variety of 1131,1142 and 1252 APs utilising AP groups.
 
I've noticed on WCS that the power of certain APs is at a low setting, even though the APs surrounding them are also at a low setting. This is causing some gaps to appear on the heatmaps. I was under the impression that the WLCs would regulate the AP power to compensate for any gaps. Currently the global TX power level assignment method algorithm is set to automatic every 600 sec.
 
Now, obviously I could change this to fixed (not ideal as I may not want all my APs to run at max power all the time) or to on demand (also not ideal due to the increased admin).
 
Is there a way I can verify that the automatic power levels are adjusting as they should? Why are there gaps appearing in my heatmaps?
 
*NB It's not just the gaps on the heatmaps, I'm getting reports of dropping wireless signals from users hence me looking at the heatmaps and they just happen to correspond.
 
WLC version 6.0.199.4
WCS version  7.0.172.0

View 4 Replies View Related

Cisco :: WLC5500 - Disable Dynamic Channel Assignment (DCA) For Group

Jan 6, 2013

Is it possible to disable DCA for a couple of APs and manually force the channels assignment ?

View 3 Replies View Related

Cisco :: 3560 - LMS 4.0 - Configure Port Assignment Only For Native Vlans Possible

Jul 19, 2011

is it possible with LMS 4.0 and VLAN Port Assignment also to configure auxiliary vlans?
 
1. I selected Configuration > Workflows > VLAN > Configure Port  Assignment.
2. Selected my device (a test switch WS-C3560-8PC-S)
3. Clicked List Ports
 
All ports were listed, port Fa0/1 has only a native vlan, the ports Fa0/2 - 8 have native and voice vlans (auxiliary) configured manually.
So when I want to configure the voice vlan for Fa0/1 the voice vlan is set as the native one.
Is it only possible to configure the native vlans with the VLAN Port Assignment of LMS 4.0 ?

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved